#ps1
echo "0 Start"

echo "1 Just IE"  
Set-ItemProperty -Path "HKLM:\Software\Policies\Microsoft\Windows\CurrentVersion\Internet Settings" -Name "Security_HKLM_only" -Type "DWORD" -Value 0x00000001
$HKLM = "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3"
Set-ItemProperty -Path $HKLM -Name "CurrentLevel" -Type "DWORD" -Value 0x00011000
Set-ItemProperty -Path $HKLM -Name "2500" -Type "DWORD" -Value 0x00000000


$tmp = 'Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
@=""
"DisplayName"="Internet"
"PMDisplayName"="Internet [Protected Mode]"
"Description"="该区域中包含所有未放在其他区域中的网站"
"Icon"="inetcpl.cpl#001313"
"LowIcon"="inetcpl.cpl#005425"
"CurrentLevel"=dword:00011000
"Flags"=dword:00000001
"1200"=dword:00000000
"1400"=dword:00000000
"MinLevel"=dword:00011000
"RecommendedLevel"=dword:00011500
"2500"=dword:00000000
"2700"=dword:00000003
"1806"=dword:00000001
"1001"=dword:00000001
"1004"=dword:00000003
"1201"=dword:00000003
"1206"=dword:00000003
"1207"=dword:00000000
"1208"=dword:00000000
"1209"=dword:00000003
"120A"=dword:00000003
"120C"=dword:00000000
"1402"=dword:00000000
"1405"=dword:00000000
"1406"=dword:00000003
"1407"=dword:00000001
"1408"=dword:00000000
"1409"=dword:00000000
"140A"=dword:00000000
"1601"=dword:00000000
"1604"=dword:00000000
"1605"=dword:00000000
"1606"=dword:00000000
"1607"=dword:00000003
"1608"=dword:00000000
"1609"=dword:00000001
"160A"=dword:00000000
"160B"=dword:00000000
"1802"=dword:00000000
"1803"=dword:00000000
"1804"=dword:00000001
"1809"=dword:00000000
"180B"=dword:00000001
"1812"=dword:00000000
"1A00"=dword:00020000
"1A02"=dword:00000000
"1A03"=dword:00000000
"1A04"=dword:00000003
"1A05"=dword:00000001
"1A06"=dword:00000000
"1A10"=dword:00000001
"1C00"=dword:00010000
"2000"=dword:00000000
"2001"=dword:00000000
"2004"=dword:00000000
"2005"=dword:00000000
"2007"=dword:00010000
"2100"=dword:00000000
"2101"=dword:00000000
"2102"=dword:00000003
"2103"=dword:00000000
"2104"=dword:00000000
"2105"=dword:00000000
"2106"=dword:00000000
"2107"=dword:00000000
"2200"=dword:00000003
"2201"=dword:00000003
"2300"=dword:00000001
"2301"=dword:00000000
"2302"=dword:00000003
"2400"=dword:00000000
"2401"=dword:00000000
"2402"=dword:00000000
"2500"=dword:00000000
"2600"=dword:00000000
"2701"=dword:00000000
"2702"=dword:00000000
"2703"=dword:00000000
"2704"=dword:00000000
"2708"=dword:00000003
"2709"=dword:00000003
"270B"=dword:00000000
"270C"=dword:00000003
"270D"=dword:00000000
"TemplateIndex"=dword:00011500
"140C"=dword:00000000
"2108"=dword:00000003
"2707"=dword:00000000
"120B"=dword:00000000
'

write-output $tmp | out-file -filepath c:\ResetIE.reg
cmd /c "reg import c:\ResetIE.reg" 2>$null
cmd /c "del  c:\ResetIE.reg" 2>$null

echo  "2 policy gpedit.msc  MaxDisconnectionTime  MaxIdleTime"  
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.SecurityProtocolType]::Tls12
Install-PackageProvider -Name NuGet -MinimumVersion 2.8.5.201 -Force
Set-PSRepository -Name PSGallery -InstallationPolicy Trusted
Install-Module -Name PolicyFileEditor  -Force 
Set-PolicyFileEntry -Path "C:\Windows\System32\GroupPolicy\Machine\Registry.pol" -Key "Software\Policies\Microsoft\Windows NT\Terminal Services" -ValueName "MaxDisconnectionTime" -Data 0 -Type DWORD 
Set-PolicyFileEntry -Path "C:\Windows\System32\GroupPolicy\Machine\Registry.pol" -Key "Software\Policies\Microsoft\Windows NT\Terminal Services" -ValueName "MaxIdleTime" -Data 0 -Type DWORD 


echo "3 install chrome"  
$Path = $env:TEMP; $Installer = "chrome_installer.exe"; Invoke-WebRequest "http://dl.google.com/chrome/install/375.126/chrome_installer.exe" -OutFile $Path\$Installer; Start-Process -FilePath $Path\$Installer -Args "/silent /install" -Verb RunAs -Wait; Remove-Item $Path\$Installer



echo "4 end"  
